Description
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master.
Remediation
References
http://www.openwall.com/lists/oss-security/2019/11/21/1
https://jenkins.io/security/advisory/2019-11-21/#SECURITY-1634
Related Vulnerabilities
CVE-2021-41151 Vulnerability in npm package @backstage/plugin-scaffolder-backend
CVE-2020-28471 Vulnerability in npm package properties-reader
CVE-2020-7691 Vulnerability in maven package org.webjars.bowergithub.mrrio:jspdf
CVE-2020-28438 Vulnerability in npm package deferred-exec
CVE-2020-13928 Vulnerability in maven package org.apache.atlas:apache-atlas